Repository navigation
fix(bin): trust pooled Treehouse worktrees across clones of the same origin - #2
Merged
Merged
Conversation
Treehouse shares one pool among every clone of an origin, so a claude spawn from a secondmate home could be handed a slot of another home's clone and fm-claude-trust refused it. Accept a pooled same-origin worktree, keep every existing refusal, and let fm_treehouse_pool_slot recognize such slots too.
… new library, bin/fm-git-origin-lib.sh. Every place that ships the wake lib together with its dependencies (fm-wake-lib.sh plus fm-path-lib.sh) never got the new file. Sourcing therefore failed with "fm-git-origin-lib.sh: No such file or directory", which broke the failing tests in shards 2, 3, 4, 6 and 8. Invariant: any set of files that ships fm-wake-lib.sh must also ship every library it sources. I found every such set by grepping for fm-path-lib.sh, and fixed each one the same way, by adding fm-git-origin-lib.sh next to fm-path-lib.sh: - bin/fm-teardown.sh: its required-source preflight list. - 12 test files, in their fixture copy/link lists: fm-turnend-guard (2 sites), fm-claude-stop-autoarm, fm-session-lock-ancestry, fm-afk-return, fm-mail-check, fm-gotmp (2 sites), fm-remote-transport-lanes, fm-remote-backlog-handoff, fm-pi-branch-extension, fm-cursor-primary, fm-extension-binding. I did not change the trust or wake logic. Verified locally, all passing (exit 0, no "not ok"): fm-turnend-guard, fm-claude-stop-autoarm, fm-afk-return, fm-gotmp, fm-remote-backlog-handoff, fm-remote-transport-lanes, fm-pi-branch-extension, fm-calm-pi-extension, fm-extension-binding, fm-mail-check, fm-cursor-primary, fm-claude-trust and fm-teardown-endpoint-safety. That covers every test file that failed in CI. fm-extension-binding finished in only 5 seconds, and I did not check whether it skipped part of its run. bin/fm-lint.sh also passes with ShellCheck 0.11.0 and actionlint 1.7.12. fm-session-lock-ancestry fails locally with "the pty-host was not reparented to init", but it fails the same way on the unmodified tree, so that is this local environment, not this change. It did not fail in CI
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Intent
Work on hive on Sonnet 5.5: hive now has its own second mate home, and its Claude workers must be able to launch from that home.
Observed 2026-10-04: the hive second mate (home
/.treehouse/firstmate-7bab20/1/firstmate, its own hive clone under that home's projects/hive) tried to spawn a Claude Sonnet 5.5 worker for hive-cutover. The shared treehouse worktree pool for hive (/.treehouse/hive-4f4202) handed out a worktree of the MAIN home's hive clone (~/firstmate/projects/hive), and Claude's workspace-trust pre-registration (bin/fm-claude-trust.sh, called from bin/fm-spawn.sh) refused it as not belonging to the second mate home's own clone, so the spawn stopped. Nothing launched, no work lost.What Changed
Risk Assessment
✅ Low: The change narrowly accepts same-origin pooled worktrees while preserving structural refusals and existing import-consent controls.
Testing
Seven focused CLI scenarios passed with product output and persisted configuration evidence. No full suite or lint ran. Authenticated Claude launch was not exercised because of the write boundary.
Evidence: Trust CLI output and persisted Claude configuration
Source: Trust CLI output and persisted Claude configuration
Pipeline
Updates from git push no-mistakes
✅ **intent** - passed
✅ No issues found.
✅ **Rebase** - passed
✅ No issues found.
✅ **Review** - passed
✅ No issues found.
Executedbash bin/fm-claude-trust.sh <worktree> <project>against disposable real Git clones and linked worktrees with worktree-local Claude stores.Parsed generated.claude.jsonto verify canonical trust, consent propagation, unrelated-key preservation, and unchanged stores after refusals.Executedfm_treehouse_pool_slotthroughbashfor same-origin and unrelated-origin clones.Rancommand -v claude; removed all disposable worktree fixtures.✅ **Document** - passed
✅ No issues found.
✅ **Lint** - passed
✅ No issues found.
✅ **Push** - passed
✅ No issues found.